PUF-Based Software Integrity Verification Circuit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for verifying the integrity of software in electronic devices are vulnerable to attacks, particularly due to the use of cryptographic keys which can compromise security and increase energy consumption and calculation time.

Innovation Solution

A process and circuit utilizing a physically unclonable function (PUF) to generate and compare verification values, ensuring the integrity of software by outputting a warning signal if differences are detected, with the PUF being specific to each device and implemented to generate reference values based on software and random values, enhancing security without relying on shared encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are used to encrypt reference values for verification, then security is improved, but energy consumption and calculation time increase

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the cryptographic key dependency from the verification process by using PUF-generated reference values that are inherently tied to the device's physical characteristics. This eliminates the need for separate key management and encryption operations, reducing energy consumption while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The PUF circuit generates reference values autonomously based on the device's own physical characteristics without requiring external cryptographic keys. The verification process becomes self-contained, using the device's inherent physical properties for both generation and verification of reference values.

Inventive Principle:
Principle #25Self-service

2Reliability

If cryptographic keys are used to encrypt reference values for verification, then security is improved, but calculation time increases

Engineering Contradiction:
ImprovesecurityVSAvoidcalculation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent removes the time-consuming cryptographic encryption and decryption operations from the verification process. By using PUF-based reference values that are naturally bound to the device, the system eliminates the need for key-based encryption while maintaining equivalent or superior security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The reference values are generated in advance during device manufacturing using the PUF circuit's physical characteristics. This preliminary generation eliminates the need for real-time cryptographic operations during verification, significantly reducing calculation time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If standard verification methods are used, then verification capability is provided, but devices are vulnerable to attacks and code modification

Engineering Contradiction:
Improveverification capabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent makes each device's verification reference values locally unique by tying them to the device's specific physical characteristics through the PUF circuit. This local differentiation ensures that reference values cannot be transferred or replicated between devices, preventing code injection and modification attacks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The PUF circuit acts as an intermediary that translates the device's physical characteristics into unique reference values. This intermediary layer provides an additional security barrier that prevents direct attacks on the verification process, as the PUF's physical unclonability protects against reverse engineering and manipulation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240020422A1Process and circuit for verifying the integrity of a software application
Publication Date: 2024.01.18 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • US20240020422A1 patent drawing
  • US20240020422A1 patent drawing
  • US20240020422A1 patent drawing

AI summary

The present disclosure relates to a process for verifying the integrity of software by a verification circuit, the process comprising: loading (401) the software into a first volatile memory; computing (402) a first verification value by the verification circuit; computing (403) a second verification value by applying a physically unclonable function to the first verification value; comparing (404), by the verification circuit, the second verification value with a reference value; and if it is found that the second verification value differs from the reference value, generating a warning signal (405) at the output of the verification circuit.